Guidance for Microsoft Defender External Attack Surface Management (Defender EASM) — discovers and inventories an organization's internet-facing assets (domains, hosts, IPs, SSL certs, ASNs, web…

MITAuto-check passedSecurity

Install Defender Easm

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill defender-easm -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills defender-easm --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/defender-easm .claude/skills/defender-easm && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
defender-easm
GitHub stars
175
Token cost
~1.9k tokens
SKILL.md length
778 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for Microsoft Defender External Attack Surface Management (Defender EASM) — discovers and inventories an organization's internet-facing assets (domains, hosts, IPs, SSL certs, ASNs, web…

  • Works in 7 steps: Seed selection. Start with primary brand… → Initial discovery run (24–72 hours).… → Label and group. Tag assets by business… → …
  • Internal asset discovery (use defender-for-cloud-hardening / Defender XDR)
  • SKILL.md covers When to use, How discovery works, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Defender Easm is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Defender External Attack Surface Management (Defender EASM) — discovers and inventories an organization's internet-facing assets (domains, hosts, IPs, SSL certs, ASNs, web pages, contacts) from the outside-in. Covers seed-based discovery, attack surface insights (CVEs, expiring certs, deprecated tech, unsanctioned cloud), labels and groups, integration with Defender for Cloud (CSPM), Defender XDR, and Sentinel, and pricing model (per asset). WHEN: Defender EASM, external attack surface…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Threat modeling, Vulnerability scanning and Pricing strategy. It works with Microsoft Defender. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • Internal asset discovery (use defender-for-cloud-hardening / Defender XDR)
  • Endpoint vuln scan (use defender-for-endpoint MDVM)
  • Sentinel hunting alone

Example prompts

  • “/defender-easm”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Seed selection. Start with primary brand domains, top-2 ASN numbers, and a few key
  2. Initial discovery run (24–72 hours). Review Candidates weekly for the first
  3. Label and group. Tag assets by business unit, region, criticality. Without labels,
  4. Attack surface insights — fix high-impact first.
  5. Integrate with the rest of the portfolio.
  6. M&A workflow. Add target-company seeds during diligence; export the candidate list
  7. Re-baseline quarterly. Brand consolidation, decommissioned subs, divested BUs all

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com
    • azure.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Defender Easm loads about 1.9k tokens when it runs. Until then it costs about 234 tokens; SKILL.md has 778 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~234
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 778 words, ~1,866 tokens.

Download SKILL.mdSave it as .claude/skills/defender-easm/SKILL.md (or your agent's skills folder).
name
defender-easm
description
Guidance for Microsoft Defender External Attack Surface Management (Defender EASM) — discovers and inventories an organization's internet-facing assets (domains, hosts, IPs, SSL certs, ASNs, web pages, contacts) from the outside-in. Covers seed-based discovery, attack surface insights (CVEs, expiring certs, deprecated tech, unsanctioned cloud), labels and groups, integration with Defender for Cloud (CSPM), Defender XDR, and Sentinel, and pricing model (per asset). WHEN: Defender EASM, external attack surface management, internet-facing inventory, shadow IT discovery, expired SSL discovery, exposed RDP discovery, unknown subdomain, attack surface insights, seed-based discovery, outside-in scanning, third-party asset risk, M&A asset discovery. DO NOT USE for internal asset discovery (use defender-for-cloud-hardening / Defender XDR), endpoint vuln scan (use defender-for-endpoint MDVM), or Sentinel hunting alone.
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Microsoft Defender EASM

Defender External Attack Surface Management (EASM) builds and maintains a continuous, outside-in inventory of an organization's internet-facing footprint and surfaces risks on those assets — expired SSL certs, exposed admin interfaces, end-of-life web tech, and known CVEs — without any agent or credentials.

When to use

  • You don't have a complete list of internet-facing assets (most orgs don't).
  • M&A: rapid discovery of an acquired company's internet footprint before integration.
  • Subsidiary / shadow IT discovery — assets registered to anyone, deployed anywhere.
  • Continuous monitoring of certificate expiration, exposed services, deprecated software.

Do not use this skill for internal asset posture (defender-for-cloud-hardening), endpoint vulnerability management (defender-for-endpoint), or generic SOC hunting (sentinel-detection-engineering).

How discovery works

EASM starts from seeds — known domains, IPs, ASNs, contacts (WHOIS), or organization names — and walks outward through DNS, WHOIS, certificate transparency logs, ASN data, and web crawling to discover related assets. Findings are placed in:

StateMeaning
Approved InventoryConfirmed yours; counts toward pricing
CandidateDiscovered but unconfirmed; review and approve/dismiss
DependencyUsed by your assets but not owned (CDN, third-party API)
Monitor OnlyTracked but not yours (e.g., a partner)

Rule of thumb: Start with 5–10 high-confidence seeds. Trust the discovery chain; don't try to add every domain manually — you'll miss the unknown unknowns.

Approach

  1. Seed selection. Start with primary brand domains, top-2 ASN numbers, and a few key email-domain WHOIS contacts. Avoid generic CDN domains as seeds (massive false positives).

  2. Initial discovery run (24–72 hours). Review Candidates weekly for the first month. Approve real ones; dismiss false positives with a reason (used to refine discovery).

  3. Label and group. Tag assets by business unit, region, criticality. Without labels, risk views are unactionable.

  4. Attack surface insights — fix high-impact first. Priority order:

    1. Exposed sensitive services (RDP/3389, SMB/445, database ports) on internet IPs.
    2. Expired or expiring SSL certs within 30 days.
    3. End-of-life software (Apache 2.2, IIS 7, OpenSSL 1.0).
    4. High/critical CVEs with known exploits on identified versions.
    5. Unsanctioned cloud — assets in a CSP not in your approved list.
  5. Integrate with the rest of the portfolio.

    • Defender for Cloud (CSPM) — EASM-discovered Azure assets correlate to Azure resources for full inside+outside view.
    • Defender XDR — exposed assets appear under attack-surface insights.
    • Sentinel — pull EASM data via REST API into a watchlist for hunting (e.g., "alert if outbound C2 destination matches an EASM-known dependency owned by us").
  6. M&A workflow. Add target-company seeds during diligence; export the candidate list as a tracked risk register for integration. Don't approve into inventory until close.

  7. Re-baseline quarterly. Brand consolidation, decommissioned subs, divested BUs all change the seed list.

Show full SKILL.md (347 more words)Show less

Guardrails

  • Approve carefully — every approval = billed asset. Treat dismiss-with-reason as important as approve; refines future discovery and controls cost.
  • Pricing is per asset/month with a generous monthly free tier; understand the meter before mass-approving CDN dependencies.
  • EASM is detection, not response. It tells you the exposed RDP exists; closing the port is a network/firewall change you must make elsewhere.
  • Do not seed competitor domains "to compare." Discovery walks aggressively; you'll create attribution noise.
  • Don't expect zero-day vuln detection. EASM matches versions to known CVEs from public banners — a stripped banner hides risk. Pair with internal vuln scanning.
  • WHOIS data quality varies by registrar / privacy-shielding. Some assets won't attribute via WHOIS — accept some manual approval workload.
  • Re-discovery cadence is days, not minutes. Don't expect EASM to catch a 1-hour exposure window; that's runtime monitoring's job.

Common anti-patterns

  • "Approved every candidate to be safe" — bill explosion and noise. Approve only yours; dismiss the rest.
  • "Seeds = every domain we've ever owned, including divested ones" — divested assets show up as attack surface forever. Re-baseline.
  • "Used EASM as the only vuln scanner" — banner-based, no auth, misses internal. Combine with MDVM/MDE.
  • "Skipped labelling, dashboards became unusable at 10K assets" — label on day 1.
  • "Treated EASM findings as alerts to triage in the SOC queue" — they're posture, not incidents. Route to asset-owner remediation, not L1 triage.
  • "Used internal asset names as seeds" — they don't resolve externally; no discovery.

Example prompts

  • Set up Defender EASM for a 3-brand global enterprise — seed strategy and labels.
  • Run an EASM discovery for an acquisition target and produce a 30-day risk register.
  • Surface expiring SSL certs in the next 30 days across approved inventory and assign to asset owners.
  • Find exposed RDP/SSH on internet-facing assets and route findings to the network team.
  • Integrate EASM data into Sentinel as a watchlist for hunting outbound C2 to owned dependencies.
  • Identify unsanctioned cloud usage (assets in clouds outside the approved list).
  • Estimate monthly cost for a 50,000-asset external footprint.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/defender-easm of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Defender Easm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Defender Easm compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Defender Easm this skillvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT
Security Auditoraiskillstore/marketplace4306 repos~2.6kAutomated safety check: PassNone
Azure External Attack Surface ManagementMicrosoftDocs/Agent-Skills777—~935Automated safety check: PassCC-BY-4.0
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
Container Securityhardw00t/ai-security-arsenal104—~2.8kAutomated safety check: PassNone
Configuring Windows Defender Advanced Settingsmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0

Similar skills

  • Security Auditor

    aiskillstore/marketplace

    Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.

    430 GitHub starsUsed in 6 repos~2.6k tokens
    SecurityAuto-check passed
  • Official

    Expert knowledge for Azure External Attack Surface Management development including configuration.

    777 GitHub stars~935 tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 11 days ago
    SecurityAuto-check: notes
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    104 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Configuring Windows Defender Advanced Settings

    mukul975/Anthropic-Cybersecurity-Skills

    Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction rules, controlled folder access, network protection, and exploit protection.

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Container Security Hardening

    sickn33/agentic-awesome-skills

    Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.

    47k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about Defender Easm

What does Defender Easm do?

Guidance for Microsoft Defender External Attack Surface Management (Defender EASM) — discovers and inventories an organization's internet-facing assets (domains, hosts, IPs, SSL certs, ASNs, web…. Defender Easm is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Defender External Attack Surface Management (Defender EASM) — discovers and inventories an organization's internet-facing assets (domains, hosts, IPs, SSL certs, ASNs, web pages, contacts) from the outside-in.

When should I use Defender Easm?

Defender Easm fits situations like: internal asset discovery (use defender-for-cloud-hardening / Defender XDR); endpoint vuln scan (use defender-for-endpoint MDVM); sentinel hunting alone.

How do I install Defender Easm in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill defender-easm -a claude-code`. Or copy the skill folder (skills/defender-easm in vinayaklatthe/microsoft-security-skills) into .claude/skills/defender-easm in your project. Claude Code loads it when a task matches its description.

How do I install Defender Easm in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill defender-easm -a codex`. Or copy the skill folder (skills/defender-easm in vinayaklatthe/microsoft-security-skills) into .agents/skills/defender-easm in your project. Codex loads it when a task matches its description.

Can I use Defender Easm in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill defender-easm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/defender-easm, .gemini/skills/defender-easm, .github/skills/defender-easm and .opencode/skills/defender-easm in your project.

What does Defender Easm need to run?

SKILL.md names no scripts, command-line tools or credentials: Defender Easm is instructions for the agent only.

Does Defender Easm access the network?

SKILL.md names 2 domains. As links in the text: learn.microsoft.com and azure.microsoft.com. This is read from the text; nothing was executed.

Is Defender Easm safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Defender Easm use?

Defender Easm is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Defender Easm use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Defender Easm?

Skills that share tags, products or a category with Defender Easm: Security Auditor (aiskillstore/marketplace, 430 stars), Azure External Attack Surface Management (MicrosoftDocs/Agent-Skills, 777 stars), Forensify (alexgreensh/repo-forensics, 188 stars) and Container Security (hardw00t/ai-security-arsenal, 104 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Defender Easm?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.